CVE-2025-5542: TOTOLINK X2000R Virtual Server Page formPortFw cross site scripting
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument servicetype leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5542?
CVE-2025-5542 has been classified as problematic due to its potential for cross-site scripting.
How do I fix CVE-2025-5542?
To address CVE-2025-5542, it is recommended to update the TOTOLINK X2000R firmware to the latest version provided by the vendor.
What component is affected by CVE-2025-5542?
CVE-2025-5542 affects the Virtual Server Page of the TOTOLINK X2000R device.
What is the attack vector for CVE-2025-5542?
CVE-2025-5542 can be exploited through manipulation of the 'service_type' argument.
Who is the vendor associated with CVE-2025-5542?
The vendor associated with CVE-2025-5542 is TOTOLINK.